WebLogic T3ЭÒé·´ÐòÁл¯ 0day ©¶´

Ðû²¼Ê±¼ä 2021-04-19

0x00 ©¶´¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-04-19

Àà   ÐÍ

RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

image.png

 

½üÈÕ £¬WebLogic±»Åû¶´æÔÚÒ»¸öT3ЭÒé·´ÐòÁл¯0 day©¶´ £¬¹¥»÷Õß¿ÉÀûÓôË©¶´Ôì³ÉÔ¶³Ì´úÂëÖ´ÐÐ £¬Ä¿Ç°¸Ã©¶´´¦ÓÚÔÚÒ°0day״̬ £¬¶øÇÒPoC/EXPÒÑÔÚGithubÉϹûÈ»¡£

Ôڸé¶´µÄpocÖÐ £¬Ê¹ÓÃÁËjava.rmi.MarshalledObjectÀà £¬²¢½«objBytesÊôÐÔ×÷Ϊ·´ÐòÁл¯µÄÁ÷ £¬´ÓÖнâÎö¹¤¾ß £¬¿ÉÒÔͨ¹ý°ÑobjBytesÌæ»»ÎªÖ¸¶¨·´ÐòÁл¯¾Í¿ÉÒÔʵÏÖweblogicºÚÃûµ¥Èƹý¡£

image.png

 

0x02 ´¦Öý¨Òé

½¨Ò齫jdkÉý¼¶µ½×îа汾 £¬²¢½ûÓÃiiop/t3ЭÒéÒÔ×÷ΪÁÙʱ»º½â´ëÊ©¡£

½ûÓÃT3ЭÒé £¬¾ßÌå²Ù×÷ÈçÏ£º

1£©½øÈëWebLogic¿ØÖÆÌ¨ £¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖÐ £¬½øÈë¡°Äþ¾²¡±Ñ¡Ïî¿¨Ò³Ãæ £¬µã»÷¡°É¸Ñ¡Æ÷¡± £¬½øÈëÁ¬½ÓɸѡÆ÷ÅäÖá£

2)ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl £¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s £¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíµ±µØ·ÃÎÊ)¡£

3£©Éú´æºóÐèÖØÐÂÆô¶¯ £¬¹æÔò·½¿ÉÉúЧ¡£

image.png

 

 

½ûÓÃIIOPЭÒé £¬¾ßÌå²Ù×÷ÈçÏ£º

µÇ½WebLogic¿ØÖÆÌ¨ £¬base_domain >·þÎñÆ÷ÌáÒª >AdminServer

image.png

 

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://github.com/hhroot/2021_Hvv/commit/8dcfdd7786ded69f404d52a162a8c4dfcbfd34b9

https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html

 

0x04 ʱ¼äÏß

2021-04-18  Ñо¿ÈËÔ±Åû¶©¶´

2021-04-19  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png